What is the risk of non-compliance with the POPI Act Copy
What is the risk of non-compliance with POPI?
Punishable offences
– fine not exceeding R10 million or imprisonment or both:
The Act sets out a number of offences. The most applicable to a business on an operational level is:
– failure to comply with an enforcement or information notice (including making a false statement in purported compliance with an information notice);
– unlawful acts by a Responsible Party and/or Third Party in connection with an account number of a Data Subject;
– failure to notify the Regulator that Processing is subject to prior authorisation.
Civil liability
A Data Subject, or the Regulator at the request of the Data Subject, can institute civil action for damages against the Responsible Party.
A Responsible Party can therefore be liable for an administrative fine and civil damages for the same offence committed.
Administrative Fines
The Information Regulator can impose an administrative fine (up to a maximum of R10 million) for non-compliance with the Act.
When determining an appropriate fine, the Information Regulator must consider the following factors:
– the nature of the Personal Information involved;
– the duration and extent of the contravention;
– whether the contravention raises an issue of public importance;
– the likelihood of damage to Data Subjects;
– whether the Responsible Party could have prevented the contravention from occurring;
– failure to carry out a risk assessment or to operate good policies, practices and procedures to protect Personal Information; and
– whether the Responsible Party has previously committed an offence.
